Data Fiduciary vs Data Processor Under the DPDP Act: Roles, Duties and Liability
Definitions, obligations, liability and a practical role-classification test.
What is the difference between a Data Fiduciary and a Data Processor?
Why the distinction matters
The DPDP Act places almost every obligation and every penalty on the Data Fiduciary. A Data Processor has no direct statutory duties to the Data Principal or the Data Protection Board. That makes role classification the first control in any DPDP programme: misclassify yourself as a Processor when you are actually a Fiduciary, and you have no consent, notice, breach or rights architecture when the Board comes calling. Classify a vendor as a Processor without a valid contract, and you carry their failures as your own.
New to the Act itself? Start with our plain-English guide to the DPDP Act. If you also run an EU programme, see DPDP vs GDPR: key differences, where these roles map to Controller and Processor.
What is a Data Fiduciary under the DPDP Act?
A Data Fiduciary is any person who, alone or with others, determines the purpose and means of processing personal data (Section 2(i)). It is the accountable party under the Act: it must obtain consent or rely on a legitimate use, issue notices, secure the data, report breaches, honour Data Principal rights and answer to the Data Protection Board. The GDPR equivalent is the Controller.
A Fiduciary the Central Government notifies under Section 10 becomes a Significant Data Fiduciary, with an India-based DPO, annual audits and algorithmic due diligence on top.
What is a Data Processor under the DPDP Act?
A Data Processor is any person who processes personal data on behalf of a Data Fiduciary (Section 2(k)). It acts under a contract and on instruction, has no direct obligations to Data Principals or the Board, and its exposure is contractual rather than statutory. The GDPR uses the same term.
Key terms
Where consent is routed through an intermediary rather than collected directly, a third role appears — see what is a Consent Manager under the DPDP Act.
- Data Fiduciary
- Section 2(i): any person who alone or in conjunction with other persons determines the purpose and means of processing of personal data. GDPR equivalent: Controller.
- Data Processor
- Section 2(k): any person who processes personal data on behalf of a Data Fiduciary. GDPR equivalent: Processor.
- Data Principal
- Section 2(j): the individual to whom the personal data relates, including a parent or lawful guardian for a child, and a lawful guardian for a person with disability.
- Processing
- Section 2(x): a wholly or partly automated operation or set of operations on digital personal data, including collection, recording, organisation, structuring, storage, adaptation, retrieval, use, alignment, combination, indexing, sharing, disclosure, dissemination, restriction, erasure or destruction.
- Significant Data Fiduciary
- A Data Fiduciary or class of Data Fiduciaries notified under Section 10 and subject to enhanced obligations.
- Joint determination
- Where two or more entities together decide purpose and means, each is a Data Fiduciary for that processing. The Act does not create a separate "joint fiduciary" regime, so contracts must allocate responsibility.
Data Fiduciary vs Data Processor: Comparison Table
| Aspect | Data Fiduciary | Data Processor |
|---|---|---|
| Core test | Decides why (purpose) and how (means) personal data is processed. | Processes only on the Fiduciary's behalf and instructions. |
| Legal basis for processing | Must obtain valid consent or rely on a Section 7 legitimate use. | None required in its own right; relies on the Fiduciary's basis. |
| Notice to Data Principals | Must issue a compliant notice before or at the time of seeking consent. | No notice obligation. |
| Accuracy and completeness | Must ensure data is accurate and complete where it is used to make decisions or shared with another Fiduciary. | Supports as instructed. |
| Security safeguards | Must implement reasonable security safeguards, including for processing done by its Processors. | Contractually bound; the Fiduciary remains liable for the Processor's failure. |
| Breach notification | Must notify the Board and affected Data Principals for every breach. | Must inform the Fiduciary under contract; no direct duty to the Board under the Act. |
| Erasure and retention | Must erase data when purpose is served or consent withdrawn, and cause its Processors to erase. | Must erase on Fiduciary instruction. |
| Data Principal rights | Must handle access, correction, erasure, grievance and nomination requests. | No direct obligation; assists the Fiduciary. |
| Grievance officer / DPO | Must publish a contact for grievances; SDFs must appoint an India-based DPO. | Not required by the Act. |
| Engaging sub-processors | May engage Processors only under a valid contract. | May onboard sub-processors only if the Fiduciary contract allows. |
| Penalty exposure | Direct: up to INR 250 crore per instance. | No direct penalty under the DPDP Act; exposure is contractual (indemnity, termination, damages). |
| Accountability principle | Section 8(1): responsible for compliance regardless of any agreement to the contrary or the Processor's conduct. | Not accountable to the Board; accountable to the Fiduciary. |
How to Decide If You Are a Data Fiduciary or a Data Processor
- Who decided to collect this data and for what business outcome? If you did, you are a Fiduciary.
- Could you continue processing if the other party terminated the contract? If yes, you are a Fiduciary.
- Do you use the data for your own analytics, product improvement, model training or marketing? If yes, you are a Fiduciary for that use, even if a Processor for the rest.
- Do you decide retention periods, security architecture or the categories of data collected? Deciding "means" at a strategic level points to Fiduciary; technical implementation choices alone do not.
- Are you a professional adviser (auditor, lawyer, CA, bank) with independent professional obligations over the data? You are almost always a Fiduciary.
Common role classifications in Indian businesses
| Scenario | Typical role | Why |
|---|---|---|
| Bank or NBFC processing customer KYC | Data Fiduciary | Decides purpose (onboarding, credit) and means. |
| Cloud hosting provider (IaaS) | Data Processor | Stores and computes on instruction; no purpose determination. |
| Payroll outsourcing vendor | Data Processor | Processes employee data to the employer's specification. |
| Payment aggregator settling merchant transactions | Data Fiduciary (own regulatory purposes) and Processor (for merchant) | Independent RBI obligations create own purposes. |
| SaaS CRM vendor | Data Processor for customer data; Fiduciary for its own account-holder data | Dual role is common; contracts must split them. |
| Marketing agency running campaigns on its own data pools | Data Fiduciary | Determines audience and purpose. |
| Chit fund or MFI branch network collecting subscriber data | Data Fiduciary | The registered entity decides purpose; agents are internal, not Processors. |
| Statutory auditor or tax adviser | Data Fiduciary | Independent professional duties govern how data is used. |
| BPO handling customer calls for a foreign client | Data Processor (DPDP) and typically Processor under GDPR | Acts on client instruction; contract must flow down DPDP terms. |
What a DPDP Data Processor Contract Must Include
The Act requires only that a Processor be engaged under a valid contract, but Section 8(1) accountability means the Fiduciary should insist on the following clauses:
- Scope and instructions: purposes, data categories, permitted operations, and prohibition on any processing outside instructions.
- Security safeguards: minimum controls mapped to Rule 6 of the DPDP Rules (encryption, access control, logging, monitoring, backups) and the right to audit.
- Breach reporting: notification to the Fiduciary without delay, with the facts needed for the Fiduciary to meet its 72-hour detailed report to the Board.
- Sub-processing: prior written approval, flow-down of identical terms, and a maintained sub-processor list.
- Retention and erasure: erasure on completion of purpose, on withdrawal of consent, or on instruction, with certification.
- Assistance with rights: timelines for supporting access, correction and erasure requests.
- Cross-border transfers: restriction to permitted jurisdictions and any SDF-specific localisation conditions.
- Liability and indemnity: indemnity for penalties and losses caused by Processor default, with insurance where proportionate.
- Log and record retention: the DPDP Rules require logs and personal data to be retained for at least one year after erasure to support Board inquiries; contracts should mirror this.
The regime this replaced put no such clauses in statute at all — DPDP Act vs IT Act SPDI Rules sets out what changed.
Frequently Asked Questions: Data Fiduciary and Data Processor
Key takeaways
- The Fiduciary decides purpose and means; the Processor acts on instruction.
- All statutory obligations and penalties sit with the Fiduciary, even for Processor failures.
- Dual roles are the norm for technology and outsourcing companies; map each processing activity separately.
- A valid written contract with security, breach, sub-processing, erasure and indemnity clauses is the Fiduciary's main control over Processor risk.